/ip firewall mangle
add action=accept chain=prerouting comment=\
"====================================================================" \
disabled=no dst-address=192.168.88.0/24 src-address=192.168.88.0/24
add action=accept chain=prerouting disabled=no dst-address=192.168.1.0/24 \
src-address=192.168.88.0/24
add action=accept chain=prerouting disabled=no dst-address=192.168.2.0/24 \
src-address=192.168.88.0/24
add action=mark-connection chain=prerouting comment=\
"====================================================================" \
connection-mark=no-mark disabled=no in-interface=ISP1 new-connection-mark=\
ISP1_conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark disabled=no \
in-interface=ISP2 new-connection-mark=ISP2_conn passthrough=yes
add action=jump chain=prerouting comment=\
"====================================================================" \
connection-mark=no-mark disabled=no in-interface=Local jump-target=\
policy_router
add action=mark-routing chain=prerouting comment=\
"====================================================================" \
connection-mark=ISP1_conn disabled=no new-routing-mark=ISP1_trafic \
passthrough=yes src-address=192.168.88.0/24
add action=mark-routing chain=prerouting connection-mark=ISP2_conn disabled=no \
new-routing-mark=ISP2_trafic passthrough=yes src-address=192.168.88.0/24
add action=mark-routing chain=output comment=\
"====================================================================" \
connection-mark=ISP1_conn disabled=no new-routing-mark=ISP1_trafic \
passthrough=yes
add action=mark-routing chain=output connection-mark=ISP2_conn disabled=no \
new-routing-mark=ISP2_trafic passthrough=yes
add action=mark-connection chain=policy_router comment=\
"====================================================================" \
disabled=no dst-address-type=!local new-connection-mark=ISP1_conn \
passthrough=yes per-connection-classifier=both-addresses:2/0
add action=mark-connection chain=policy_router disabled=no dst-address-type=\
!local new-connection-mark=ISP2_conn passthrough=yes \
per-connection-classifier=both-addresses:2/1